A critical vulnerability in Cisco's Secure Firewall Management Center, carrying the maximum possible severity score of 10 out of 10 on the Common Vulnerability Scoring System, is being actively exploited in Germany more than six months after patches were released. Cisco updated its security advisory on 10 September 2026 to confirm ongoing attacks, with the first documented incidents traced to August.
The vulnerability allows an unauthenticated attacker to send a crafted HTTP request to a vulnerable FMC appliance and gain root-level access. Root is the highest privilege tier on the system. An attacker with root access can modify firewall rules, disable security functions, and install persistent backdoors. No credentials are required. No user interaction is needed.
What the FMC actually controls
The Secure Firewall Management Center, known as FMC, is the central platform for configuring and monitoring Cisco firewalls across enterprise networks. It is not a peripheral tool. Compromising FMC does not mean compromising a single firewall. It means compromising the system that controls every firewall in the organisation's perimeter, from rule sets to traffic inspection policies to threat response configurations.
The attack itself is straightforward. An attacker sends a specially crafted HTTP request to the FMC web interface, and if the system is unpatched, the request executes with root privileges. CVSS 10 vulnerabilities are supposed to represent the most urgent class of security flaws: trivially exploitable, with severe consequences and no mitigating factors.
What attackers have done with their access remains unclear. Cisco's advisory does not detail specific post-compromise activity, and independent analysis has yet to fill the gap. Security professionals familiar with the incidents assume that attackers have at minimum disabled firewall rules, weakened security policies, or established persistent access for later use. The absence of documented malicious activity does not mean none has occurred. A compromised firewall management platform is an ideal foothold for long-term espionage or lateral movement within corporate networks, precisely the kind of access sophisticated attackers prefer to keep quiet.
Six months of available patches
Cisco disclosed the vulnerability and released patches in March 2026. The fact that systems are still being exploited in September reveals a significant gap between vulnerability disclosure and remediation in German enterprise networks. The Heise report that brought wider attention to the ongoing exploitation noted that administrators had evidently not brought all FMC installations up to date.
The phrasing is restrained. The situation is not: a maximum-severity flaw in a security management platform, with a patch available for half a year, still being successfully exploited. Every day an FMC remains unpatched is a day an attacker with a simple HTTP request can take full control of an organisation's firewall infrastructure.
Why administrators have not patched
Enterprise patching for critical infrastructure is often slow. Change management processes, testing requirements, and approval workflows can delay deployment for weeks or months. Some organisations may lack full visibility into which devices are vulnerable. Others may be running FMC versions that cannot accept the patch without a broader platform upgrade, turning a security fix into a major project.
In some cases, the firewall management platform itself may simply be overlooked. Firewalls attract attention. The systems that manage them, sitting on internal networks with less direct exposure, can fall off the priority list. Germany's Federal Office for Information Security, the BSI, has repeatedly urged organisations to improve their patching practices, but the pace of remediation for critical infrastructure remains a persistent weakness across the country.
The wider European patching deficit
Germany is not alone in struggling with patching discipline, though the current exploitation appears concentrated there. Across Europe, enterprise patching timelines for critical vulnerabilities routinely stretch well beyond the 48-to-72-hour window that security professionals recommend for maximum-severity flaws. The European Union Agency for Cybersecurity has highlighted the gap between vulnerability disclosure and remediation as a systemic problem in its annual threat landscape reports.
The Cisco FMC case illustrates a specific danger: the device that manages security policy becomes the attack vector. Organisations that invest in next-generation firewalls but neglect the management platform are effectively building a fortress with an unlocked back door. When the management layer is compromised, the firewalls it controls cannot be trusted, even if the firewalls themselves are fully patched.
Immediate steps for affected organisations
Cisco's advisory is unambiguous: install the March 2026 patches immediately. Organisations that cannot patch straight away should restrict network access to the FMC management interface, limiting connections to trusted internal networks and specific IP ranges. Monitoring FMC logs for unusual HTTP requests would help detect exploitation attempts against systems that remain vulnerable.
For organisations that may already have been compromised, the response is more complex. Patching a compromised system does not remove an attacker who has established persistent access. A full forensic investigation, including review of firewall rule changes and network traffic logs dating back to at least August 2026, would be necessary to determine whether a breach has occurred. Any firewall managed by a compromised FMC instance should be treated as potentially untrustworthy until independently verified.
Organisations
Cisco